CVE-2021-3325
Published Jan 27, 2021Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because…
Vendor/product archive
4 CVEs tagged to fibranet / monitorix — 2 Critical, 0 High, 2 Medium, 0 Low, 0 Unrated.
Monitorix 3.13.0 allows remote attackers to bypass Basic Authentication in a default installation (i.e., an installation without a hosts_deny option). This issue occurred because…
Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HT…
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.
Monitorix before 3.10.1 allows XSS via CGI variables.